NegativeSEO.ICU logo — negative SEO reference and recoveryNegativeSEO.ICUNegative SEO reference & recovery
Abstract stepped block illustration representing Redirect Hijacking
Link-Based AttackYour backlink profile

Redirect Hijacking

Situational Works only under specific conditions, and rarely otherwise.

A spam or penalized domain pointed at your site by permanent redirect: what it can do, what it cannot, and the one version that is genuinely dangerous.

What redirect hijacking is

Redirect hijacking is the pointing of a domain you do not control at a site you do own, so that everything the attacker's domain carries arrives at your address uninvited. A domain is the registered name a website answers to - example.com, and every page beneath it. The attacker aims theirs at yours with a 301 redirect: a Hypertext Transfer Protocol (HTTP) response whose status code, 301, means moved permanently and tells browsers and crawlers to treat the destination as the real address from now on.

The domains chosen are picked for their history, not their traffic - spammy, hacked, already penalized, or carrying a past life in pharmacy, gambling or adult content. The bet is that Google reads the redirect as an instruction to consolidate: to make your URL the canonical one, the single address Google treats as authoritative for that content, and to move the redirecting domain's links and reputation onto it. Negative SEO by inheritance.

Three forms turn up, and they look different in your data. A whole-domain 301 at your homepage is the common one. Deep, per-URL 301s map thousands of the attacker's URLs onto matching paths on your site, manufacturing a far larger footprint from a single configuration file - which matters, because the resulting link count measures the attacker's URL structure rather than anything reaching you. Meta refresh and JavaScript redirects are followed as redirects but behave differently in crawling and in your logs.

Two neighboring attacks are not this one, and the remedies differ entirely. A 302 - a temporary redirect - aimed at you attacks which URL gets indexed, not your link profile. A cross-domain rel="canonical" naming your URL is an attribution claim rather than a redirect, and a canonical is a hint Google may decline to honor.

The answer Google gave, and the date on it

On 21 December 2022, John Mueller of Google was asked on X whether the standing advice about ignoring bad incoming links - that most sites never need to disavow anything - also holds when somebody redirects an entire penalized website at you. His answer was one word: "Yes."

Put that beside what the same person said in June 2014 - Google was "usually good at catching these cases," and he had "never seen a case where this caused an issue for a good site" - and the useful part is the change in register. The 2014 answer is hedged. The 2022 answer is not. The position did not reverse; it hardened over eight years, and anyone quoting the 2014 wording today is quoting the weaker version of a claim Google later stated flatly.

The mirror image is more instructive still. Asked in March 2019 about routing spammy links through an intermediate domain to launder them, Mueller said the 301 "basically makes the main site canonical, meaning the links go directly there - you might as well skip the detour." Google resolves the redirect and evaluates the links at their real source. Anything that can be evaluated at source can be discounted at source. That symmetry, not reassurance, is why the attack fails.

The error underneath most redirect panic is the belief that a penalty is an object attached to a domain, traveling down a redirect like water down a pipe. What follows a redirect is links, judged on their merits. So an owner who redirects their own penalized domain to a fresh one does not escape - those bad links are still theirs - while a stranger redirecting junk at you hands you nothing, because those links were never counted for you.

The written policies agree. Google's spam policies cover sneaky redirects and expired domain abuse, and both describe conduct by the operator of the redirecting domain; nothing there penalizes a site for redirects it did not create and cannot switch off. The ground shifted underneath the attack, too. Penguin 4.0, in September 2016, moved Google's stated behavior from demoting sites to devaluing links; the December 2022 link spam update put machine learning on neutralizing link spam. Once the model is ignore-the-bad-links, a vector whose entire payload was links has nothing left to deliver.

One caveat belongs here rather than in a footnote: no public experiment with a disclosed method has redirected a penalized domain at a healthy site and measured the outcome. Google's statements are the best evidence available, and they are statements rather than data.

What it still costs you, honestly

This is not a zero. It is that none of the residue is the thing people are afraid of.

Brand and search-result confusion. A redirecting domain confusable with yours, or containing your trademark outright, appears in brand searches, sits in a customer's address bar for the moment before the redirect resolves, and shows up in third-party referral data. That is a trademark problem with a trademark remedy, and it is the residue most often ignored because it does not look like an SEO problem.

Crawl and analytics contamination. Redirected traffic arrives as real requests. Googlebot spends crawl budget on URLs that were never yours; analytics fills with a referring domain nobody has heard of at close to a 100 percent bounce rate; weak hosting buckles under a large campaign. None of that moves rankings, and all of it corrupts the numbers you would use to decide whether rankings moved.

A cleanup already in progress. A site already under an unnatural-links manual action - a penalty applied by a human reviewer at Google and shown to the owner in Search Console - has a harder story to tell in a reconsideration request when a campaign lands mid-cleanup.

Notice what is absent: ranking loss on a healthy site. Anyone selling monthly protection against inbound redirects is selling protection against the one item not on the list.

The redirect that does real damage is on your own server

This is the case most often filed under the wrong heading, and separating it is the most useful thing this page does.

If your own site has been compromised so that it redirects visitors to spam - often only mobile visitors, or only those arriving from a search result, which is why the owner never sees it - that is not negative SEO. It is an intrusion. It is genuinely penalizable, it draws a hacked-content finding, and it recurs until the entry point is closed. The symptoms overlap enough that owners spend a week on a disavow file while injected code keeps serving pharmacy pages to Googlebot.

The test takes minutes: request your own URLs as Googlebot and as a mobile browser, with and without a search referrer, and compare. If your server is issuing the redirect, run an incident response - find the injected rule in the server configuration, the plugin or the template, clean it, patch the vulnerability, rotate every credential, then request a review. Assume reinfection until the entry vector is provably shut.

The direction of the redirect is the whole diagnosis. Someone else's domain pointing at you is, on current evidence, close to harmless. Your domain pointing at someone else is an emergency.

One HTTP request tells three attacks apart

Before theorizing about motive, read the response. Request the suspicious domain and look at the status line and the Location header. A 301 aimed at your URL is this vector. A 302 is temporary and is an attack on which URL gets indexed. No redirect at all, but a rel="canonical" in the suspect page's head naming your URL, is an attribution claim. Three attacks, one request to separate them - and it is remarkable how much analysis gets written before anyone checks a status code.

The rest of the evidence lives in four places. Search Console, under Links then Top linking sites, usually surfaces the redirecting domain, because Google follows the redirect and attributes the source's links; one unfamiliar domain with an implausible link count is the signature. Server access logs are the clearest evidence and the one defenders skip - and they are also the evidence that survives in a legal matter. Analytics shows the referral spike. Security and Manual Actions in Search Console is the only place a penalty is ever confirmed.

Rule out the mundane first: an expired domain that legitimately used to link to you and was bought by somebody who redirected it, an old property from a former partner, referrer spam that touches analytics and never reaches Google, and a core update that landed the same week.

What to do, in order - and when the answer is nothing

  1. Confirm the redirect exists and points inbound, by reading headers, before anything else.
  2. Check manual actions. None outstanding means nothing to remediate, and a reconsideration request with nothing to reconsider produces no reply.
  3. Baseline the damage. Compare organic sessions and impressions against the date the redirect started and against the published update calendar. If nothing moved, nothing needs fixing - and that is the usual finding.
  4. Preserve evidence while it exists. Header captures with timestamps, log excerpts, registration and hosting records, screenshots. A redirect is switched off with one line of configuration and the proof vanishes with it. This step stays mandatory even when the fix is optional.
  5. Consider doing nothing. On the ranking question, this is the correct course in most cases.
  6. Disavow only against a very large and clearly artificial profile, at domain level. Google restricts the tool to "considerable" spammy links that "caused or likely will cause a manual action" and warns that "if used incorrectly, this feature can potentially harm your site's performance". Whether a disavow reaches the links behind a redirect has never been documented.
  7. Block at the edge only for load or fraud reasons, never as a ranking fix. Refusing a referrer does not change what Google sees.

What does not help: mass-disavowing unrelated domains because one showed up; blocking Googlebot; setting up a counter-redirect, which achieves nothing mechanically and creates liability you did not have; and publicly accusing the registrant, which converts a nuisance into a defamation exposure of your own making.

Where the law actually reaches

The strongest routes here have nothing to do with rankings, which is what most write-ups miss.

If the redirecting domain is confusingly similar to a registered mark, the Uniform Domain-Name Dispute-Resolution Policy is the established administrative route to transfer or cancellation, and the Anticybersquatting Consumer Protection Act, 15 U.S.C. section 1125(d), is the statutory one. A redirect that promises one destination and delivers another also has the shape of a false statement about the nature or origin of goods and services - Lanham Act section 43(a) territory - where standing is governed by Lexmark Int'l, Inc. v. Static Control Components, Inc., 572 U.S. 118 (2014): injury to a commercial interest in reputation or sales, proximately caused by the deception. That test matters precisely because it does not require proving a ranking loss.

Then say the next part plainly, because much of the writing on this subject implies otherwise: no decided case applying any of these theories to a malicious redirect has been located for this page. They are the frames counsel will work in, not precedents to point at.

Two less glamorous routes usually matter more. A spam report to Google under those policies costs nothing, though Google's current documentation notes that the submission text is sent verbatim to the reported site owner - so write it factually and keep personal information out. And an abuse report to the registrar or host is often faster than any search-engine process, particularly where the redirecting domain is itself a hacked property whose owner will be glad to hear from you.

What people get wrong about redirect attacks

Treating a toxicity score as a penalty. No third-party backlink tool has any input into Google's systems. A score is a vendor's opinion, sold to you, and it is the single most common reason a site owner starts remediating a problem that does not exist.

Buying protection. There is nothing to subscribe to here. You cannot stop a stranger configuring a redirect on their own server, and the ranking consequence Google describes is that there is none. Anyone selling monthly monitoring against inbound redirects is selling vigilance over an event you should be prepared to ignore.

Missing the compromise because the symptom looked external. The expensive mistake on this page, and worth repeating: check the direction of the redirect before you check anything else.

Letting the evidence evaporate. The default advice here is to do nothing about your rankings. It is never to do nothing about your records. Capture headers and logs the day you notice, because the attacker erases their side in a minute and you will be left describing something you cannot show.

Frequently asked questions

A strange domain 301 redirects to my website. Will Google penalize me?

On Google's own statement, no. Asked in December 2022 whether the advice to ignore bad incoming links covers an entire penalized domain redirected at your site, John Mueller answered yes, without qualification, and no published mechanism transfers a third party's penalty to a destination that did not create the redirect. Confirm it in Search Console under Security and Manual Actions.

Should I disavow the domain that is redirecting to me?

Usually not. Google restricts the disavow tool to considerable spammy links that caused or likely will cause a manual action, and warns that incorrect use can harm performance. With no manual action and no measurable traffic loss, a disavow file solves a problem you do not have while creating a chance of causing one. The narrow exception is a very large, obviously artificial profile - and even then it may not reach the links behind the redirect.

How do I tell a redirect attack from a hacked site?

By direction. Request the suspect domain: if it returns a 301 or 302 pointing at you, the redirect lives on their server. Then request your own URLs as Googlebot and as a mobile browser, with and without a search referrer. If your site is the one redirecting, you have been compromised - clean the injection, patch the hole, rotate credentials, then ask for a review.

The redirecting domain uses my brand name. Is that different?

Yes, and it is the version worth acting on. Ranking harm from inbound redirects is poorly evidenced; a domain confusable with your mark causes customer confusion regardless of how Google treats the links. That is a trademark matter with established routes, and it belongs with counsel rather than in a disavow file.

My rankings dropped the same week a redirect appeared. Is that proof?

No, and treating it as proof is how people buy the wrong repair. Check the drop against the published algorithm update calendar, then against your own technical changes, then against seasonality. Coincidence in a single week is weak evidence at the best of times, and this vector carries an unusually strong on-record denial.

Top